vBulletin 5.x¶à¸ö¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17271£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-17132£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4


Îó²î¸ÅÊö


vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾ÅäºÏ¿ª·¢µÄÒ»¿î¿ªÔ´µÄÉÌÒµWebÂÛ̳³ÌÐò¡£¡£¡£ ¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬£¬£¬£¬vBulletin ¹Ù·½Ðû²¼ÁËÒ»¸öÈ«ÐÂÇå¾²²¹¶¡£¬£¬£¬£¬£¬£¬¸Ã²¹¶¡ÐÞ¸´ÁËCVE±àºÅΪCVE-2019-17271µÄSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬ÒÔ¼°CVE±àºÅΪCVE-2019-17132µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£¡£¡£


CVE-2019-17271 SQL×¢ÈëÎó²î


SQL×¢ÈëÎó²îÊÇÁ½¸ö¡°read in-band and time-based¡±µÄSQL×¢ÈëÎÊÌ⣬£¬£¬£¬£¬£¬ËüÃDZ£´æÓÚÁ½¸ö×ÔÁ¦µÄ¶ËµãÉÏ£¬£¬£¬£¬£¬£¬ÔÊÐí¾ßÓÐÊÜÏÞÖÆÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿â¶ÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£


£¨1£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼üת´ïµ½¡°ajax/api/hook/getHookList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬£¬ÔÚºǫ́¾ÙÐÐSQLÅÌÎÊ֮ǰûÓо­ÓÉ׼ȷÑéÖ¤Óë¹ýÂË¡£¡£¡£ ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã£¬£¬£¬£¬£¬£¬Í¨¹ý¡°read in-band¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÓû§¾ßÓС°canadminproducts¡±»ò¡°canadminstyles¡±µÄÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬í§Òâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£


£¨2£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼üת´ïµ½¡°ajax/api/widget/getWidgetList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬£¬ÔÚºǫ́¾ÙÐÐSQLÅÌÎÊ֮ǰûÓо­ÓÉ׼ȷÑéÖ¤Óë¹ýÂË¡£¡£¡£ ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã£¬£¬£¬£¬£¬£¬Í¨¹ý¡°time-based¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÓû§¾ßÓС±canusesitebuilder¡±µÄÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬í§Òâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£


CVE-2019-17132 Ô¶³Ì´úÂëÖ´ÐÐÎó²î


vBulletin forum´¦Öóͷ£Óû§¸üÐÂÍ·Ïñ(Óû§µÄСÎÒ˽¼Ò×ÊÁÏ¡¢Í¼±ê»òͼÐÎÌåÏÖ)ÇëÇóʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÊÇͨ¹ý¡°data[extension]¡±ºÍ¡°data[filedata]¡±²ÎÊýת´ïµ½¡±ajax/api/User/updateAvatar¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬£¬ÔÚÓÃÓÚ¸üÐÂÓû§µÄavatar֮ǰûÓлñµÃ׼ȷÑéÖ¤¡£¡£¡£ ¡£¡£¡£¡£Õâ¿ÉÒÔÓÃÀ´×¢ÈëºÍÖ´ÐÐí§ÒâµÄPHP´úÂë¡£¡£¡£ ¡£¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÖÎÀíÔ±ÆôÓá°ÉúÑÄÍ·ÏñΪÎļþ¡±Ñ¡Ïî(¸ÃÑ¡ÏîĬÈϱ»½ûÓÃ)¡£¡£¡£ ¡£¡£¡£¡£


ͨ¹ýÍøÂç¿Õ¼äËÑË÷ÒýÇæ¿ÉÒÔµÃÖª£¬£¬£¬£¬£¬£¬ÔÚÈ«Çò¹æÄ£ÄÚ£¬£¬£¬£¬£¬£¬¶Ô»¥ÁªÍø¿ª·ÅµÄvBulletinÍøÕ¾Óнü3Íò¸ö£¬£¬£¬£¬£¬£¬ÆäÖн϶àÍøÕ¾Îª¹ú¼Ê´óÐÍÆóÒµËùά»¤µÄ¹ú¼ÊÉçÇøÂÛ̳£¬£¬£¬£¬£¬£¬ÒÔÊǸÃÎó²îÓ°ÏìÃæ½Ï´ó¡£¡£¡£ ¡£¡£¡£¡£


Îó²îÑéÖ¤


CVE-2019-17132

POC£ºhttps://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html¡£¡£¡£ ¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2¡£¡£¡£ ¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html

https://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html